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Electronic casino gaming with authentication and improved security 
Infa-odufctipii 

The present invention relates generally to electronic gaming -machines 
or consoles and In particular the Invention provides an improved system tor 
executing casino games in RAM as opposed to the conventional unalterable 
ROM. "the improvements provide an authentication process based upon 
digital signatures, with the U.S. filgital Signature Standard (tISSJ being the 
preferred means of implementation. 

For the sake of clarity the following terms are defined for the purpose 
of this specification. 

A gambling machine , usually referred to as a gaming machine, is a 
traditional gaming machine. Typical examples include slot machines of the 
type made by Aristocrat Leisure Industries or 1GT. 

A casino refers to the operator of gambling machines. 
A digital signature is a pair of large numbers represented in a computer 
as strings of binary digits. The digital signature is computed using a set of 
rules fi e., the USA) and a set of parameters such that the identity of the 
signatory and integrity of the data can be verified. 

Strong encryption is the encryption of data such that it is 
computationally infeasible for a third patty - for example a government 
agency - to retrieve the encrypted data without a key. 

A hash , or message digest is the output from a function that produces 
a value that is unique for any message input into ii A one-way hash 
produces an output that is computationally difficult to relate to the input It 
Is also computationally difficult to produce two different messages with the 
same message digest. 

An unforgeable log is produced by chaining together hash values such 
that the nth entry in the log is dependent on the (n-l)'h entry, and thus 
previous entries cannot be altered without re-computing the whole chain. 

A logic cage is a secure area inside the gaming machine that cannot be 
accessed without sufficient security clearance. 
References 

"The Olgital Signature Standard" U.S. Federal Information Processing 
Standards Publication IBB 

"The Secure Mash Standard" U.S. federal Information Processing 
Standards Publication 180-1 
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"Cryptographic Support far Secure Logs on Untrusted Machines' 1 by 
firuce Schneler and John kelsey (available at 
http://www.counterpane.com/secure-logs. html) 
BacitgfrouMti of ffielnvimtjbtt 

traditionally, microprocessor based gaming machines store their 
program contents in unalterable ROM or ERROM During installation and 
after a large Jackpot payout, the machine is physically inspected and the 
ERROMs are removed, these RRROMs are placed In a verification device 
which produces an output string using a known algorithm usually referred to 
as a hash function, this string is compared against a string that has been 
already generated when the game software was approved by the gaming 
jurisdiction. Authentication is achieved by a match of the approved string 
and the RRROM generated string. 

Hie main disadvantage of such a system is that the current limited 
capacity of RRROM technology ensures that games cannot be as sophisticated 
as if they were stored in an alternative medium such as a hard disk or CD- 
ROM, the other problem with using RAM is that it cannot be extracted and 
placed in a verification device, since the contents of the RAM are necessarily 
volatile. 

Another system, disclosed and described In U.S. Rat No. 9,643,088 
uses a private key to encrypt a message digest of the approved copy of the 
software, and thus produce an unalterable digital signature which can be 
decrypted with a corresponding public key and compared against a message 
digest generated by an unalterable RRROM in the gaming machine. 

the disadvantage of the above invention is that It relies on strong 
encryption, currently subject to export restrictions from the U.S. and other 
countries, this software can only be signed by one party and if a single 
private key is compromised, the whole system Is compromised. 

A related problem that exists is that of version control. Once a gaming 
machine software program is found to be faulty, a modification or 'patch' Is 
usually distributed. Unfortunately, conventional RRROM based machines, 
and the disclosed system above, have no method implemented of ensuring 
that the earlier version of the software is not re-installed, either deliberately 
or by accident, later. Once software is approved, it is impossible for the 
machine to revoke that approval. If a rogue element was able to 'sneak past' a 
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Jurisdiction a dubious piece of software, there would be no way (o stop it 
being used In a casino, eveu after detection 
Summary of the Invention 

The Invention provides a gaming machine with enhanced capability 
for storing games due to enhanced security and authentication capabilities. 

According to a first aspect the present Invention provides a 
programmable controller, Including a readable and writable storage means to 
hold a program during Its execution by the programmable controller, and 
program authentication means comprising digital signature verification 
means which verifies a digital signature associated with the program and 
prevents execution of the program If the digital signature is not valid. 

According to a second aspect the present Invention provides a method 
of verifying a program or a program component for a programmable 
controller, lucludlng a readable and writable storage means to hold a program 
during lis execution by the programmable controller, and program 
authentication means comprising digital signature verification means which 
verifies a digital signature associated with the program, and the method 
Including a step of verifying the digital signature against a key, and 
preventing execution of the program If the digital signature is not valid. 

Preferably, the digital signature is generated fay a method that does not 
Include encryption such that de-encryption is not performed during the 
digital signature verification. 

According to a third aspect the present invention provides a 
programmable controller, including a readable and writable storage means to 
hold a program during Its execution by the programmable controller, and 
program authentication means comprising digital signature verification 
means which verifies each of a plurality of digital signatures associated with 
the program and prevents execution of the program If any one of the digital 
signatures is not valid. 

According to a fourth aspect the present invention provides a method 
of verifying a program or a program component for a programmable 
controller, Including a readable and writable storage means to hold a program 
during Its execution by the programmable controller, and program 
authentication means comprising digital signature verification means which 
verifies each of a plurality of digital signatures associated with the program, 
and the method Including steps of verifying each of the digital signatures 
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against a respective key, and preventing execution of the program If any one 
of the digital signatures is not valid. 

Preferably the or each digital signature Is generated by a method that 
does not Include encryption such thai : de-encryption Is not pelformed during 
the digital signature verification. 

In one embodiment, the programmable controller Is used to control the 
operation of a game played on an electronic gaming machine and the signed 
program Is a game program or a component of a game program. 

Preferably multiple signatures may be applied to the game software, to 
ensure that only software approved by not only the manufacturer, but also 
the jurisdictional authority and optionally the casino itself, is executed by 
the machine 

Preferably also a system is provided for revoking signature keys. This 
can be password based - a password is entered which allows one of the 
public signatures stored in the machine to be changed. Alternatively, a 
revocation certificate can be used, which must be valid, or the revocation 
system can be time based, where the machine stores a set of signatures, good 
for say 10 years, and the current active signature is based upon the current 
system clock. 

A system of equivalent signatures is also preferably provided, such that 
any one of these signatures can be used as part of the verification. Ideally a 
manufacturer will have at least one signature for its office in each 
Jurisdiction. Any one could be used to sign a game, but It would be apparent 
in the event of a problem where the responsibility would lie, and could be 
revoked easily. 

Preferably a system for version control Is also included, such that once 
a later version of software runs on a gaming machine it is then impossible to 
run an earlier version of the same software. This would preferably 
permanently revoke faulty games once a fix had been issued. 

Preferably any signature and version changes are held In secure 
unforgeable logs updated after each change to help detect possible fraud.- 
Preferably also the unforgeable logs are Implemented using tamper-proof 
devices such as smartcards to ensure that the log can never be deleted. 
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Brief Description of the Drajyjngg 

Embodiments of the present invention will now be described by way of 
example with reference to the accompanying drawings in which: 

Figure i illustrates a conventional gaming machine in which the 
5 present invention may be Implemented; 

figure 2 is a block diagram of a control unit according to the present 
invention; 

figure 3 Is a diagrammatic representation of a method of signature 
generation and verification according to the present Invention; 
id figure 4 is a flow diagram of a software approval process according to 

the present invention; and 

figure 5 Is a flow diagram illustrating a method of executing approved 
software according to the present Invention. 
Detailed Description of the preferred embodiments 
IS In the following detailed description the methodology of the 

embodiments will be described, and it is to be understood that it is within 
the capabilities of the non-inventive worker in the art to introduce the 
methodology on any standard microprocessor-based gaming machine or 
gaming console by means of appropriate programming. 
20 Referring to figure 1 of the drawings, the first embodiment of the 

invention is Illustrated In which a slot machine 40, of the type having a video 
display screen 41 which displays a plurality of rotatable reels 42 carrying 
symbols 43, is arranged to pay a prize on the occurrence of a predetermined 
symbol or combination of symbols. 
2S In the slot machine 40 Illustrated in figure 1, the game is initiated by a 

push button 44, however, it will be recognized by persons skilled In the art 
that this operating mechanism might be replaced by a pull handle or other 
type of actuator In other embodiments of the Invention. The top box 49 on 
top of the slot machine 40 carries the artwork panel 35 which displays the 
30 various winning combinations for which a prize is paid on this machine. 

The program which implements the game and user Interface is run on 
a standard gaming machine control processor 100 as Illustrated schematically 
In figure 2. This processor forms part of a controller 110 which drives the 
video dlsplayscreen 141 and receives Input signals from sensors 144. The 
sensors 144 may be touch sensors, however, in alternative embodiments 
these may be replaced by a pull handle or another type of actuator such as 
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button 44 in figure 1. The controller 110 also receives Input pulses from a 
mechanism 120 Indicating the user has provided sufficient credit to begin 
playing. The mechanism 120 may be a coin Input chute, a banJc note 
acceptor (bill acceptor), a credit card reader, or oilier type of vairJatibii 
5 device. The controller 120 hIso drives a payout mechanism 130 which tor 
example may be a coin output 

The controller 110 also includes ROM 170 in which fixed and secure 
program components are heJd. This ROM may also contain part or all of a 
program to perform a program verification function for programs running on 
10 the CPU 100 out of RAM 150 or loaded onto or from the disk 100. 

Alternatively, the program verification may he performed by a stand 
alone verification system 140 interposed between the RAM 150, the disk 100 
and the CPU 100. The verification system may make use of a tamper proof 
storage element such as a smart card 180 (or a device containing a smart card 
IS chip, or the verification system 140 may itself be implemented as a smart 
card or smart card chip in which case, it will not require the separate smart 
card 180. An input/Output function 190 is also provided for the CPU to 
communicate with a gaming machine network for administration 
participation in system wide prizes and bonuses and for downloading of 
20 game programs. 

The game played on the machine shown in Figures 1 and 2 Is a 
relatively standard game which includes a 3 by 5 symbol display and allows 
multiple pay lines. 

Slot machines such as those of the type described with reference to 
23 Figures 1 and 2 can be adapted to embody the present invention with 

generally only a software change to modify the functions of some of the user 
interfaces of the machine. 

The system, when built will consist of an electronic gaming machine, 
with standard features such as graphics capability, a monitor, sound output 
30 and interfaces to gaming hardware such as hoppers, bill acceptors etc. The 
gaming machine would also have a sophisticated central processor, say a 
Pentium or PowerPC for example, with a large amount of RAM, a storage 
device such as a hard disk, CD-ROM or remote network storage and 
optionally a smartcard Interface. 
35 The machine would furthermore have an unalterable EPROM which 

would have stored in It program code to perform the DSS algorithm, also 
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know as the DSA. It would also contain code to perform the Secure Mash 
Algorithm (SHA-1), the designated U.S. federal standard message digest 
algorithm, "this EPROM would be able to be extracted and Inspected by the 
traditional means, in alternative Implementations, otRer digital signature 
algorithms could be used such as GOST, ESlGN or even the previously 
disclosed RSA method which requires encryption. 

figure 3, copied from the U.S. federal standard ftPS 180-1, describes 
the operations that produce and verify a digital signature using USA and 
SHA-1. An Important distinguishing characteristic of this system Is that It 
does not use encryption to produce a digital signature. It Is thus not subject 
to export restrictions from the US and other countries. 

Each set of software that is to be installed in any gaming machine at 
present must be approved, botb by the gaming jurisdictional authority and by 
the machine manufacturer. It also may need to be approved by the casino in 
which the machine will reside. In the preferred implementation, all 
interested parties will digitally sign each piece of approved software prior to 
installation. The process of game software being produced, approved and 
authenticated would proceed as in figure 4. 

These signatures will be stored with the software on a mass storage 
device inside the gaming machine. When the machine needs to load a piece 
of software, or upon an external command after a significant event such as a 
jackpot payout, it will execute the SHA-1 program code in the £f RDM on the 
software being loaded, and then perform a t)SA verification operation using 
the SHA-1 output as one of the parameters. The USA verification operation 
will be repeated for every digital signature stored with the software, and all 
must be valid, so that it Is Impossible to execute program code that has not 
been approved by the manufacturer, the Jurisdictional authority and 
optionally the casino and/or other parties. The process of executing pre- 
approved software would proceed as in figure 8. 

A significant benefit of multiple signatures, as opposed to other 
disclosed systems which use only one, is that it protects all parties from a 
rogue element working within either the manufacturer, the jurisdiction or the 
casino. To successfully Install a fraudulent piece of software In a gaming 
machine that uses this system would require a concerted conspiracy 
involving trusted personnel working for all parties. 
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To perform the digital signature verification, It Is also necessary that 
the machine store public keys for the appropriate parties - jurisdiction, casino 
and manufacturer. In the preferred Implementation, these keys are stored in 
iEPROKt j cflM he modified at suitable times By a progmmlwreaiH "the 
8 JEPROM, under strict security conditions, this enables signatures to be 
revoked if compromised, or periodically updated. In an alternative 
implementation, a plurality of signature public keys are stored in the 
unalterable EPKOM and variables stored In EEPROM indicate which of these 
signatures are active, in another alternative Implementation, a tamper-proof 
id device such as a smartcard stores the public keys. Hie program code in the 
EPftOM passes the output from the SttA-1 algorithm to the smartcard along 
with the signature values stored with the software. Hie smartcard then 
performs the CSS or other signature verification and returns either an 
authentication or denial code to the gaming machine. Once revoked, the 
IS smartcard will not allow keys to be re-enabled. 

Since it will be possible to change the digital signatures that 
authenticate software running In the machine, it is important that an 
unforgeable log is kept of all software changes or signature changes, this can 
be achieved by the use of a hash chain, where every entry in the log is 
20 'hashed* with the previous log entry's hash value, in a preferred 

implementation, this hash chain, or the most recent part of it, is stored 
within a tamper-proof device such as a smartcard or the traditionally used 
logic cage. A smartcard is preferred, since it can have a secret unique 
identification code, and is thus non-reproducible and unforgeable itself. 
25 Program code stored in the unalterable EPKOM accesses the smartcard 
during signature or software update. Since the latest hash value would 
always be stored on the smartcard, it would be Impossible to change the 
software without creating a log entry. This would ensure that all 
modifications to the software stored on the machine was accurately logged 
30 which L would be extremely useful in the event of a major Jackpot payout. 
The fcPfcOM can be proven to be unaltered by 1 the conventional means of 
placing it in a verification device. 

A more detailed description of a possible Implementation of a hash- 
chain unforgeable log can be found in the paper "Cryptographic Support for 
35 Secure Logs on Untrusted Machines" - see references above. 
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Each signature for a file would be linked to the file, but need not be 
contained within the file. In the event of a signature key revocation, new 
signatures may have to he downloaded from a network device or using the 
iiiiciyneVopiFaWmoB'e; Iri TBl's'caserTKeFew signatures being 
6 downloaded would indicate which file they are to attach to, and which 

signature they replace. This would be more economical than re-downloadittg 
the whole software set upon a signature key change. 

In an alternative implementation, multiple public keys for each 
corresponding signature are stored. At any one time, only one for each 

id Interested party would be active. Hie schedule for selecting which public 
keys are active could be time-based, so signatures would In effect have a 
lifetime. Periodically, the machine would have to be updated with the new 
signatures as either a maintenance task or upon the payments of an 
additional license fee to the manufacturer or jurisdiction. 

IS in the event of an authentication failure due to signatures (and 

therefore the license to run the software] expiring, it could be implemented 
that the casino would have a 'grace' period to obtain new keys before the 
machine completely refused to run the software, for example, the machine 
could display a notice, similar to that found on computer shareware 

20 products, informing of the license expiry that would have to be manually 
accepted by the machine operator every time the machine was reset 

In the alternative implementation, it would also be possible to have 
multiple signatures active for each party at any one time. One possibility 
would be that these would correspond to different divisions within the 

25 manufacturer or jurisdiction. This would aid tracing in the event of a 
software or security failure. 

Another security aspect that will be implemented in the gaming 
machine is the concept of version control. Each digitally signed piece of 
software stored on the mass storage device within the machine will have an 

30 associated identification code and version number. It will be impossible to 
download software with a corresponding Identification code and an earlier 
version number. 

It will be appreciated by persons skilled in the art that numerous 
variations and/or modifications may be made to the invention as shown in 
35 the specific embodiments without departing from the spirit or scope of the 
invention as broadly described. The present embodiments are, therefore, to 
be considered in all respects as illustrative and not restrictive. 
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CLAIMS 

1. A programmable controller, including a readable and writable storage 
means to hold a urogram during, its execution by the pragraniniable 
controller, and program authentication means comprising digital signature 
verification means which verifies a digital signatute associated with the 
program and prevents execution of the program if the digital signature is not 
valid, the digital signature being generated by a method that does not include 
encryption such that de -encryption is not performed during the digital 
signature verification. 

2. The controller as claimed in claim 1, wherein a plurality of signatures 
are applied to the game software. 

3. A programmable controller, including a readable and writable storage 
means to hold a program during its execution by the programmable 
controller, and program authentication means comprising digital signature 
verification means which verifies each of a plurality of digital signatures 
associated with the program and prevents execution of the program if any 
one of the digital signatures is not valid. 

4 The electronic gaming machine as claimed in claim 2 or 3, wherein 
one of the digital signatures is applied to the software by or on behalf of a 
manufacturer of the electronic gaming machine. 

5. The controller as claimed in claim 2, 3 or 4, wherein one of the digital 
signatures is applied to the software by or on behalf of a jurisdictional 
authority that has jurisdiction to authorize use of the game in a location in 
which the game is installed. 

6. The controller as claimed in claim 2, 3, 4 or B, wherein one of the 
digital signatures is applied to the software by or on behalf of a casino in 
which the electronic gaming machine is installed. 

7. The controller as claimed in any one of claims 1 to 8, wherein the 
programmable controller is used to control the operation of a game played on 
an electronic gaming machine and the program with which the digital 
signature is associated is a game program or a component of a game program. 

8. The controller as claimed in any one of claims 1 to 7, wherein the 
signature verification means stores one or more public signature keys in 
secure storage and uses a public signature key from the secure storage to 
verify the digital signature associated with the game program. 
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9. The controller as claimed In claim 8, wherein the signature verification 
means Includes signature revocation means for removing public signature 
keys from a set of valid keys as a method of revokingslgnature keys. 

10. The controller as claimed lii claim 9, wherein the signature revocation 
means Is activated by a password such that when the password is entered it 
allows a particular public signature stored In the verification means to be 
changed or deleted. 

11. The controller as claimed in claim 9 or 10, wherein a digital revocation 
certificate can be used, which must be validated by the validation means 
before It causes a public signature key to be revoked. 

12. The controller as claimed in claim 9, 10 or 11, wherein revocation is 
time based, whereby the machine stores a set of public signature keys, which 
are valid for a fixed period of time, after which they are automatically 
revoked. 

13. The controller as claimed in claim 12, wherein the fixed period before 
automatic revocation is a period of 10 years. 

14. The controller as claimed in claim 12 or 13, wherein identification of a 
current active public signature is based upon comparison of a time stamp 
embedded in the signature with a time and date obtained from a current time 
value from a system clock. 

15. The controller as claimed in any one of claims 8 to 14, wherein a 
plurality of equivalent signatures are provided in the secure storage, such 
that any one of the equivalent signatures can be used as part of the 
verification authorization. 

IB. The controller as claimed in claim IS, wherein each of the equivalent 
signatures Is identifiable as being associated with a person or entity 
responsible for issuing or authorizing the program 

17. The controller as claimed in any one of claims 1 to 16, wherein the 
verification program records versions of a program that have been verified 
and will not re-verlfy versions earlier than the latest version that it has 
already verified. 

18. The controller as claimed In claim 17, wherein the record of verified 
program versions Is stored in a secure log and entries In the record are 
unforgable and unalterable after being written. 

19. The controller as claimed in claim 18, wherein a record of digital 
signature key updates Is kept In the secure log. 
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20. The controller as claimed in claim 18 or 19, wherein the secure log Is 
recorded In a tamper proof device. 

21 the controller as claimed In claim 20, wherein the tamper proof de vice 
Is a smartcard or contains a smartcard chip. 

22. A method of verifying a program or a program component for a 
programmable controller, including a readable and writable storage means to 
hold a program during Its execution by the programmable controller, and 
program authentication means comprising digital signature verification 
means which verifies a digital signature associated with the program, the 
digital signature being generated by a method that does not include 
encryption and the method Including a step of verifying the digital signature 
against a key, in which de-encryption is not performed during the digital 
signature verification, and preventing execution of the program If the digital 
signature is not valid. 

23. Hie method as claimed in claim 22, a plurality of signatures are 
applied to the game software. 

24. A method of verifying a program or a program component for a 
programmable controller, including a readable and writable storage means to 
hold a program during its execution by the programmable controller, and 
program authentication means comprising digital signature verification 
means which verifies each of a plurality of digital signatures associated with 
the program, and the method including steps of verifying each of the digital 
signatures against a respective key, and preventing execution of the program 
if any one of the the digital signatures is not valid. 

25. The method as claimed in claim 23 or 24, wherein one of thB digital 
signatures Is applied to the software by or on behalf of a manufacturer of the 
electronic gaming machine. 

28. The method as claimed In claim 23 or 24 or 25, wherein one of the 
digital signatures is applied to the software by or on behalf of a Jurisdictional 
authority that has jurisdiction to authorize use of the game in a location in 
which the game is installed. 

27. The method as claimed In claim 23 or 24 or 25 or 2B, wherein one of 
the digital signatures Is applied to the software by or on behalf of a casino in 
which the electronic gaming machine is installed. 

28. The method as claimed In any one of claims 22 to 27, wherein the 
programmable controller Is used to control the operation of a game played on 
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a« electronic gaming machine and the program with which the digital 
signature Is associated Is a game program or a component of a game program. 

29. The method as claimed In any one of claims , 22 to 28, wherein the 
signature verification means stores one or more public signature keys in 
secure storage and uses a public signature key from the secure storage to 
verify the digital signature associated with the game program. 

30. The method as claimed in claim 29, wherein the signature verification 
means Includes signature revocation means for removing public signature 
keys from a set of valid keys as a method of revoking signature keys. 

31. The method as claimed in claim 30, wherein the signature revocation 
means is activated by a password such that when the password is entered it 
allows a particular public signature stored in the verification means to be 
changed or deleted. 

32. The method as claimed In claim 30 or 31, wherein a digital revocation 
certificate can be used, which must be validated by the validation means 
before It causes a public signature key to be revoked. 

33. The method as claimed In claim 30, 31 or 32, wherein revocation Is 
time based, whereby the machine stores a set of public signature keys, which 
are valid for a fixed period of time, after which they are automatically 
revoked. 

34. The method as claimed in claim 33, wherein the fixed period before 
automatic revocation Is a period of 10 years. 

38. The method as claimed in claim 33 or 34, wherein Identification of a 
current active public signature is based upon comparison of a time stamp 
embedded in the signature with a time and date obtained from a current time 
value from a system clock. 

36. The method as claimed in any one of claims 29 to 35, wherein a 
plurality of equivalent signatures are provided in the secure storage, such 
that any one of the equivalent signatures can be used as part of the 
verification. 

37. The method as claimed In claim 30, wherein each of the equivalent 
signatures Is identifiable as being associated with a person or entity 
responsible for issuing or authorizing the program. 

38. The method as claimed in any one of claims 22 to 37, wherein the 
verification program records versions of a program that have been verified 
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and will not re-verify versions earlier than the latest version that It fans 
already verified 

.JB?* method as claimed in claim 38, wherein therecord of verified 
program versions Is stored In a secure Tog and entries in the record are 
S unibrgable and unalterable after being written. 

40. The method as claimed in claim 39, wherein a record oi* digital 
signature key updates is kept in the secure log. 

41. The method as claimed in claim 39 or 40, wherein the secure log is 
recorded in a tamper proof device. 

10 42. The method as claimed in claim 41, wherein the tamper proof device is 
a smartcard or contains a smartcard chip. 
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